Always-Incorrect Control Flow Implementation in Spring Cloud Stream - CVE-2026-59305
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information and affect message integrity.
The vulnerability exists due to improper interceptor handling in the message sending functionality when sending messages. A remote privileged user can send a message to disclose sensitive information and affect message integrity.
User interaction is required.